Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-42874— Denial of service (DOS) in SAP NetWeaver (remote service for Xcelsius)

CVSS 7.9 · High EPSS 0.05% · P16
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-42874

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Denial of service (DOS) in SAP NetWeaver (remote service for Xcelsius)
Source: NVD (National Vulnerability Database)
Vulnerability Description
SAP NetWeaver remote service for Xcelsius allows an attacker with network access and high privileges to execute arbitrary code on the affected system due to insufficient input validation and improper handling of remote method calls. Exploitation does not require user interaction and could lead to service disruption or unauthorized system control. This has high impact on integrity and availability, with no impact on confidentiality.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
不对称的资源消耗(放大攻击)
Source: NVD (National Vulnerability Database)
Vulnerability Title
SAP NetWeaver 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SAP NetWeaver是德国思爱普(SAP)公司的一套面向服务的集成化应用平台。该平台主要为SAP应用程序提供开发和运行环境。 SAP NetWeaver存在安全漏洞,该漏洞源于输入验证不足和远程方法调用处理不当,可能导致执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
SAP_SESAP NetWeaver (remote service for Xcelsius) BI-BASE-E 7.50 -

II. Public POCs for CVE-2025-42874

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-42874

登录查看更多情报信息。

Same Patch Batch · SAP_SE · 2025-12-09 · 12 CVEs total

CVE-2025-428809.9 CRITICALCode Injection vulnerability in SAP Solution Manager
CVE-2025-429289.1 CRITICALDeserialization Vulnerability in SAP jConnect - SDK for ASE
CVE-2025-428788.2 HIGHSensitive Data Exposure in SAP Web Dispatcher and Internet Communication Manager (ICM)
CVE-2025-428777.5 HIGHMemory Corruption vulnerability in SAP Web Dispatcher, Internet Communication Manager and
CVE-2025-428767.1 HIGHMissing Authorization Check in SAP S/4 HANA Private Cloud (Financials General Ledger)
CVE-2025-428756.6 MEDIUMMissing Authentication check in SAP NetWeaver Internet Communication Framework
CVE-2025-429046.5 MEDIUMInformation Disclosure vulnerability in Application Server ABAP
CVE-2025-428726.1 MEDIUMCross-Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
CVE-2025-428735.9 MEDIUMDenial of Service (DoS) in SAPUI5 framework (Markdown-it component)
CVE-2025-428915.5 MEDIUMMissing Authorization check in SAP Enterprise Search for ABAP
CVE-2025-428965.4 MEDIUMServer-Side Request Forgery (SSRF) in SAP BusinessObjects Business Intelligence Platform

IV. Related Vulnerabilities

V. Comments for CVE-2025-42874

No comments yet


Leave a comment